Fix base64 decode error for keystore signing - #1
Conversation
PR Summary by QodoFix keystore base64 decode in GitHub Actions signing step
AI Description
Diagram
High-Level Assessment
Files changed (1)
|
There was a problem hiding this comment.
Pull request overview
Updates the GitHub Actions build workflow to more reliably decode a base64-encoded Android signing keystore secret during release APK builds, addressing base64: invalid input failures.
Changes:
- Switches keystore decoding to use
base64 --decode --ignore-garbageto tolerate whitespace/newlines in the secret. - Adjusts the command used to feed
KEYSTORE_B64intobase64during workflow execution.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| KP: ${{ secrets.KEYSTORE_KEY_PASSWORD }} | ||
| run: | | ||
| printf '%s' "$KEYSTORE_B64" | base64 -d > "$RUNNER_TEMP/ghost-rain.jks" | ||
| echo "$KEYSTORE_B64" | base64 --decode --ignore-garbage > "$RUNNER_TEMP/ghost-rain.jks" |
Code Review by Qodo
1. Permissive base64 decode
|
| KP: ${{ secrets.KEYSTORE_KEY_PASSWORD }} | ||
| run: | | ||
| printf '%s' "$KEYSTORE_B64" | base64 -d > "$RUNNER_TEMP/ghost-rain.jks" | ||
| echo "$KEYSTORE_B64" | base64 --decode --ignore-garbage > "$RUNNER_TEMP/ghost-rain.jks" |
There was a problem hiding this comment.
1. Permissive base64 decode 🐞 Bug ☼ Reliability
The workflow decodes KEYSTORE_B64 with base64 --ignore-garbage, which silently discards any non-base64 characters instead of failing fast on malformed input. This can turn a paste-corrupted secret into a different .jks file and defer the failure to Gradle signing with harder-to-diagnose errors.
Agent Prompt
## Issue description
The workflow currently uses `base64 --decode --ignore-garbage` to decode the keystore secret. This weakens validation by silently discarding non-base64 characters, which can produce a corrupted keystore file and move the error to a later signing step.
## Issue Context
This decoded file is then referenced via `keystore.properties` and consumed by the Android Gradle signing configuration, so failing fast at decode time is valuable for diagnosability.
## Fix Focus Areas
- .github/workflows/build.yml[20-34]
## Suggested fix
Replace the permissive decode with a strict decode while only normalizing expected whitespace (e.g., remove `\r`/newlines) and keep decode errors fatal.
Example:
```bash
printf '%s' "$KEYSTORE_B64" | tr -d '\r\n' | base64 --decode > "$RUNNER_TEMP/ghost-rain.jks"
```
(Optionally, add a small validation step to ensure the sanitized string contains only base64 characters before decoding.)
ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools
Problem
The workflow fails with
base64: invalid inputwhen decoding theKEYSTORE_B64secret. This happens because:printf '%s'can produce output thatbase64 -drejectsbase64oropenssl) often contains newlines, whichbase64 -drejects by defaultFix
Changed the decode command to:
printf '%s'back toecho(was working before)--ignore-garbageflag so newlines/whitespace in the base64 string are handled gracefully